CVE-2023-30851
published 2023-05-25CVE-2023-30851: Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to…
PriorityP431medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.66%
49.9th percentile
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users who have a HTTP policy that applies to multiple `toEndpoints` AND have an allow-all rule in place that affects only one of those endpoints. In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies. This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cilium | cilium | < 1.11.16 | 1.11.16 |
| cilium | cilium | — | — |
| cilium | cilium | — | — |
| cilium | cilium | >= 1.12.0 < 1.12.9 | 1.12.9 |
| cilium | cilium | >= 1.13.0 < 1.13.2 | 1.13.2 |
| github.com | cilium_cilium | >= 0 < 1.11.16 | 1.11.16 |
| github.com | cilium_cilium | >= 1.12.0 < 1.12.9 | 1.12.9 |
| github.com | cilium_cilium | >= 1.13.0 < 1.13.2 | 1.13.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Potential HTTP policy bypass when using header rules in Cilium in github.com/cilium/cilium
osv·2024-08-20
CVE-2023-30851 Potential HTTP policy bypass when using header rules in Cilium in github.com/cilium/cilium
Potential HTTP policy bypass when using header rules in Cilium in github.com/cilium/cilium
Potential HTTP policy bypass when using header rules in Cilium in github.com/cilium/cilium
OSV
Potential HTTP policy bypass when using header rules in Cilium
osv·2023-05-22
CVE-2023-30851 [MEDIUM] Potential HTTP policy bypass when using header rules in Cilium
Potential HTTP policy bypass when using header rules in Cilium
### Impact
This issue only impacts users who:
- Have a HTTP policy that applies to multiple `toEndpoints` AND
- Have an allow-all rule in place that affects only one of those endpoints
In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies.
### Patches
This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.
### Workarounds
Rewrite HTTP rules for each endpoint separately. For example, if the initial rule looks like:
```
egress:
- toEndpoints:
- matchLabels:
k8s:kind: echo
- matchLabels:
k8s:kind: example
toPorts:
- ports:
- port: "8080"
protocol: TCP
rules:
http:
- method: "GET"
```
It should be rewritten to:
```
egress:
- toEndpoints:
- matchLabe
GHSA
Potential HTTP policy bypass when using header rules in Cilium
ghsa·2023-05-22
CVE-2023-30851 [MEDIUM] CWE-693 Potential HTTP policy bypass when using header rules in Cilium
Potential HTTP policy bypass when using header rules in Cilium
### Impact
This issue only impacts users who:
- Have a HTTP policy that applies to multiple `toEndpoints` AND
- Have an allow-all rule in place that affects only one of those endpoints
In such cases, a wildcard rule will be appended to the set of HTTP rules, which could cause bypass of HTTP policies.
### Patches
This issue has been patched in Cilium 1.11.16, 1.12.9, and 1.13.2.
### Workarounds
Rewrite HTTP rules for each endpoint separately. For example, if the initial rule looks like:
```
egress:
- toEndpoints:
- matchLabels:
k8s:kind: echo
- matchLabels:
k8s:kind: example
toPorts:
- ports:
- port: "8080"
protocol: TCP
rules:
http:
- method: "GET"
```
It should be rewritten to:
```
egress:
- toEndpoints:
- matchLabe
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/cilium/cilium/releases/tag/v1.11.16https://github.com/cilium/cilium/releases/tag/v1.12.9https://github.com/cilium/cilium/releases/tag/v1.13.2https://github.com/cilium/cilium/security/advisories/GHSA-2h44-x2wx-49f4https://github.com/cilium/cilium/releases/tag/v1.11.16https://github.com/cilium/cilium/releases/tag/v1.12.9https://github.com/cilium/cilium/releases/tag/v1.13.2https://github.com/cilium/cilium/security/advisories/GHSA-2h44-x2wx-49f4
2023-05-25
Published